CVE-2026-48138
NI grpc-device, InstrumentStudio, instrumentstudio
There is an out-of-bounds read vulnerability in the NI grpc-device streaming API due to a missing bounds check that may result in a denial of service. Successful exploitation requires an attacker to supply a specially crafted write request. This affects NI grpc-device 2.17.0 and prior versions.
- CVSS
- 8.7
- EPSS
- 0.49% 39.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.19